Privacy Policy
MentBro Ltd · Company No. 17163881 · Last updated: April 2026
1. Introduction
MentBro Ltd ("MentBro", "we", "our", "us") is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights under UK data protection law.
MentBro Ltd is the data controller for personal data processed through the Service. Company No. 17163881, registered in England and Wales.
If you have any questions about how we handle your data, contact us at aryan@mentbro.com.
2. What Data We Collect
2.1 Data You Provide Directly
When you register and use MentBro, we collect:
- Name, email address, and password (via Supabase Auth)
- Date of birth (to verify age eligibility)
- City and school or university name
- Career goals, five-year vision, and self-identified obstacles (onboarding)
- Academic subjects and results (optional)
- LinkedIn profile information (entered manually by you — we do not access LinkedIn directly)
- Instagram handle and content description (optional)
- Target industries and professional interests
- Content you submit during AI coaching conversations
2.2 Data Generated Through Your Use
- Your life plan, goals, and weekly reset records
- University application details you enter
- Daily tasks and progress data
- Life stage designations and history
- Industry intelligence content generated for you
2.3 Technical and Usage Data
- IP address and approximate location
- Device type, browser, and operating system
- Pages visited, features used, and session duration
- Error logs and performance data
3. How We Use Your Data
- Create and manage your account
- Provide AI coaching responses personalised to your profile and goals
- Generate and maintain your life plan
- Process subscription payments via Stripe
- Send service-related communications such as account confirmations and billing updates
- Improve and develop the Service through aggregated, anonymised analytics
- Detect and prevent fraud, abuse, or security incidents
- Comply with our legal obligations
4. Legal Bases for Processing
- Contract: Processing necessary to provide the Service under our Terms and Conditions
- Legitimate interests: Improving the Service, ensuring security, and preventing fraud, where this does not override your rights
- Legal obligation: Where processing is required to comply with applicable law
- Consent: Where you have given explicit consent for optional profile fields or marketing communications
5. Data Storage and Security
Your data is stored securely using Supabase, a cloud infrastructure provider. All data is protected by row-level security, meaning your data is accessible only to you and to MentBro systems acting on your behalf.
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. These include encrypted connections (HTTPS/TLS), access controls, and regular security reviews.
No method of electronic storage or transmission is completely secure. While we take all reasonable precautions, we cannot guarantee absolute security.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, regulatory, or fraud prevention purposes.
Aggregated, anonymised data that cannot identify you may be retained indefinitely for analytical and product development purposes.
7. Sharing Your Data
We do not sell your personal data. We share your data only in the following limited circumstances:
- Supabase: Our database and authentication infrastructure provider, acting as a data processor on our behalf
- Stripe: Our payment processor for handling subscription billing. Stripe operates as an independent data controller for payment data under their own privacy policy
- Anthropic: Our AI provider. Coaching queries are processed through the Anthropic Claude API. MentBro relies on Anthropic's enterprise privacy commitments. Please review Anthropic's privacy policy at anthropic.com/privacy
- Legal compliance: Where required by law, court order, or regulatory authority
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you and ensure the receiving party is bound by equivalent data protection obligations
8. International Data Transfers
Some of our third-party providers, including Supabase and Anthropic, may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK ICO, to protect your data in accordance with UK GDPR.
9. Your Rights
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data, subject to legal retention obligations
- Right to restriction: Request that we limit how we process your data in certain circumstances
- Right to portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at aryan@mentbro.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Cookies and Tracking
MentBro uses essential cookies and local storage to maintain your session and application state. We use analytics tools to understand how the Service is used in aggregate. These tools use anonymised or pseudonymised data and do not identify you personally.
We do not use advertising cookies or share data with advertising networks.
11. Shareable Cards
MentBro allows you to generate and share visual cards based on your life plan. These cards display only your first name and a key focus statement. No other personal data is included. By sharing a card, you consent to that limited information being visible to others. You control when and whether to share.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or in-app notification before they take effect. The date at the top of this document reflects the most recent version.
13. Contact
Data Controller: MentBro Ltd
Company No.: 17163881
Email: aryan@mentbro.com
Website: mentbro.com
← Back to MentBro